Impact
The vulnerability allows authenticated users with an API key to bypass object-level authorization checks in Phproject's REST API issue endpoints. By skipping the allowAccess() routine, attackers can read restricted issue data and comments, including sensitive email addresses, and post unauthorized comments to issues they should not access. This constitutes a confidentiality breach and unauthorized modification of data, corresponding to CWE-862.
Affected Systems
The affected product is Phproject from Alanaktion, for all releases prior to version 1.8.7. Users running any early 1.8.x or older versions are at risk, as the fix was introduced starting with v1.8.7.
Risk and Exploitability
The issue carries a CVSS base score of 7.1. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires an authenticated API key; the description explicitly states that an attacker must hold a valid key, so the exploitation is constrained to environments where keys are distributed or the system is compromised. Given the moderate severity and lack of public exploit evidence, the risk is significant for systems that expose the REST API to privileged users or have weak API key management.
OpenCVE Enrichment